Executive brief
The Price Alert extension for Joomla, which allows customers to receive notifications about product price changes, contains a security flaw. An unauthenticated attacker can exploit this to access the website's underlying database. This could lead to the theft of sensitive information, including user credentials and site configuration data.
Technical details
An SQL injection vulnerability exists in the Price Alert component (com_price_alert) for Joomla version 3.0.2. The flaw is located in the 'subscribeajax' view and 'pricealert_ajax' task, where the 'product_id' parameter is not properly sanitized before being used in a database query. A remote, unauthenticated attacker can exploit this by sending a specially crafted HTTP request to the vulnerable endpoint. Successful exploitation allows for the extraction of sensitive data from the database, including administrative credentials and system configuration, via boolean-based or error-based SQL injection techniques.
Affected products
- Weborange Price Alert 3.0.2
Timeline
- 2017-08-24: disclosed: Initial exploit published on Exploit-DB
- 2026-06-19: advisory: CVE published and NVD record created